Subject: Re: default route and private networks
To: David Young <dyoung@pobox.com>
From: Thor Lancelot Simon <tls@rek.tjls.com>
List: tech-security
Date: 04/13/2005 17:39:34
On Wed, Apr 13, 2005 at 12:29:10PM -0500, David Young wrote:
>
> is preferred. IPv4 should likewise prefer a private sources (192.168/16,
> 10/8, ...) when the destination is private, a link-local (169.254/16)
> for link-local destinations, and global source for a global destination.
You want to be careful with this; it takes us even further away from the
"strong host model" and may break the assumptions of people who've built
certain kinds of firewalls.
--
Thor Lancelot Simon tls@rek.tjls.com
"The inconsistency is startling, though admittedly, if consistency is to be
abandoned or transcended, there is no problem." - Noam Chomsky